Privacy Policy
Effective date: 16 July 2026
Last updated: 6 August 2026
Doppio is operated by Sam Bessey in Australia ("Doppio", "we", "us", or "our"). This policy explains how Doppio handles personal information and Google user data when you use the Doppio website, documentation, Google Workspace add-on for Google Slides, required Chrome extension, presenter dashboard, participant application, application programming interfaces (APIs), preview service, and related support services (together, the Service).
The Workspace add-on and Chrome extension cooperate as one product. The extension safely tracks the current slide, prevents stale or wrong-slide changes, supplies previews, and displays interactive content during a presentation. The add-on sends the information needed to create and manage that content to Doppio's API and Firebase services. The participant application receives the active poll or takeaway and sends votes to the Doppio API.
At a glance
- Doppio uses Google account and presentation information only to provide, secure, support, and improve the user-facing Service.
- Doppio does not sell personal information or Google user data.
- Doppio does not use Google user data for personalised advertising, transfer it to data brokers, or use it for credit or lending decisions.
- The extension is limited to Google Slides and Doppio services. It does not collect unrelated browsing history or the contents of unrelated pages.
- Product analytics in the Chrome extension are off until you turn them on. Nothing is collected, and no analytics identifier is created, unless you opt in.
- Presenters control the events, polls, takeaways, and results associated with their account and can request deletion at any time.
Information we handle
Account and identity information
When a presenter signs in, we handle their email address, Google or Firebase account identifier, Doppio account and plan information, authentication and refresh tokens, session identifiers, and an anonymous extension installation identifier. Google identity tokens are used to authenticate requests. Tokens are not used as analytics properties and should never be written in full to application logs.
We use this information to sign the presenter in, associate events with the correct account, enforce access and plan limits, permit collaboration, prevent fraud, provide support, and maintain account security.
Google Slides and presentation information
When a presenter uses Doppio in Google Slides, the Service may access or process:
- the active presentation's ID, title, and Google Slides URL;
- slide and page-object IDs, ordered slide IDs, the currently selected slide, slide-change and selection state, and limited object geometry needed to place or align Doppio content;
- poll questions, answer options, colours, chart style, background, timing, vote limits, live-result and countdown settings;
- takeaway titles, text, labels, and links;
- event names, codes, identifiers, presentation metadata, and collaborator email addresses;
- Doppio-generated preview images and information about images or charts inserted by Doppio; and
- synchronisation state, including the current-slide cursor and interaction-version state stored in Firestore.
The Workspace add-on processes some presentation data inside Google Apps Script and transmits the fields needed to create, update, preview, present, or delete Doppio content to the Doppio API. The sidebar also reads and writes limited cursor and version state in Firebase/Firestore so cooperating components remain on the same slide. The preview service temporarily renders the poll content supplied by the presenter to produce an image for the slide.
Doppio does not request access to all files in Google Drive. Its Slides permission is limited to the presentation in which the add-on is being used. Doppio does not access speaker notes or unrelated slide content unless that content is part of an object the presenter asks Doppio to inspect or change.
Information observed by the Chrome extension
On supported Google Slides pages, the extension may process the active Slides tab and URL, presentation and slide identifiers, relevant Slides DOM or object identifiers, selected-slide state, object geometry, messages from the Doppio sidebar, preview state, and overlay or presentation state. This information is used to detect the current slide, prevent stale edits, position Doppio charts, provide previews, and render Doppio during a presentation.
Most observed page state is processed transiently in the browser. The extension reads the active Slides tab URL in the browser to work out which presentation you are on; that URL is not included in the product analytics or diagnostic reports the extension sends. The extension stores authentication state, Doppio deck mappings, settings, cached compatibility selectors, analytics identifiers, and active-session identifiers in chrome.storage.local. It transmits only the data described in this policy to Google, Doppio's API, Firebase, and our product-analytics provider as applicable.
The extension does not collect the user's general browsing history, unrelated tabs, passwords, or the contents of non-Slides pages. Its access to the active tab is used only for the disclosed Doppio features.
Participant and results information
Participants generally do not need to provide a name or email address. When a participant joins or votes, we may handle:
- an event code, run ID, poll or slide ID, and anonymous participant or device identifier;
- the selected answer, a unique vote identifier, vote status, and timestamps;
- locally stored vote history and pending-vote state used to prevent duplicate votes and safely retry interrupted submissions;
- join source, browser and device information, IP address, request metadata, and short-lived participant access tokens; and
- aggregate results, participant counts, slide transitions, session history, and takeaway-link clicks.
The anonymous browser identifier is stored locally on the participant's device. IP addresses and request metadata may be processed for delivery, security, abuse prevention, diagnostics, and rate limiting. Doppio does not use participant IP addresses to identify participants for the presenter.
Presenters choose the poll content and determine the context in which Doppio is used. They are responsible for providing any notice or obtaining any consent required from their audience.
Product analytics, diagnostics, and support
We collect limited product events such as extension installation, sign-in, presentation start and end, poll activation, chart placement method, participant join source, poll views, vote confirmation, results views, errors, request timing, security events, and service health. These events help us operate, secure, troubleshoot, and improve Doppio.
Analytics in the Chrome extension are opt-in. They are disabled until you enable them in the extension's options. While they are disabled, the extension sends no product events and does not even create an analytics identifier. If you later turn analytics off, the extension deletes the analytics identifiers held on that installation.
When you do opt in, extension analytics are deliberately narrow. Events are attributed to a randomly generated installation identifier, which is replaced by your Firebase account identifier once you sign in. Your email address is never used as an analytics identifier. The extension strips event codes, event IDs, slide IDs, poll IDs, and interaction IDs from every event before sending it, so analytics cannot be used to reconstruct your deck's structure or the join details of a session. A pseudonymous run identifier is retained so that a single presentation run can be correlated across the extension, the API, and the participant application when diagnosing a fault.
Doppio uses PostHog for product analytics. The participant application may use privacy-protected session replay to diagnose usability or reliability issues; form inputs are masked and automatic interaction capture is disabled. We do not intentionally send poll questions, answer text, vote choices, Google tokens, or unrelated presentation content to PostHog. Participant analytics use pseudonymous device or session information. Identifiers other than those described above may be processed by the Doppio API and the participant application where they are required to run a live session, rather than for product analytics.
Crash and diagnostic reports
The Chrome extension can send an automatic diagnostic report when it hits a fault, such as a chart failing to load or a placeholder it cannot find. These reports are minimised before they leave your browser:
- the page URL is removed entirely, so the report never carries the presentation ID;
- identifying fields, including any user and media identifier, are replaced with a short one-way correlation token, so repeated faults can be recognised as affecting the same subject without transmitting who or what that subject is;
- error messages and stack traces are truncated to fixed limits; and
- reporting is rate-limited to a small number of reports per minute.
Diagnostic reports are sent to Doppio's API and are used only to find and fix faults. Doppio's API forwards them to Sentry, our error-tracking provider, together with the error type, severity, browser user agent, the correlation tokens described above, and the slide and event identifiers associated with the fault. Authorisation headers and cookies are stripped, and obvious token fields are redacted, before an event is recorded. Sentry is used only for diagnosing and fixing faults.
If you contact us, we collect your contact details, correspondence, attachments, and the technical or account information needed to resolve the request. We will ask before accessing specific presenter content unless access is necessary to investigate a security incident, prevent abuse, or comply with law.
How we use information
We use information to:
- authenticate users and provide the add-on, extension, participant experience, dashboard, previews, live results, history, and exports;
- keep the sidebar, extension, API, participant view, and presentation display synchronised;
- save and retrieve presenter-created events, polls, takeaways, settings, and results;
- enforce access controls, account entitlements, participant limits, vote limits, and rate limits;
- detect, investigate, and prevent errors, fraud, abuse, security incidents, and unauthorised access;
- provide support and communicate about the Service;
- understand feature adoption and improve user-facing functionality, performance, and reliability; and
- comply with legal obligations and enforce our terms.
Where a law requires a legal basis, we process information as necessary to perform our contract with the presenter, based on our legitimate interests in operating and securing the Service, with consent where requested, and to comply with legal obligations. Where an organisation provides Doppio to managed users, that organisation may be responsible for choosing the appropriate legal basis and giving required notices.
Google API data and Limited Use
Doppio's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
In particular, Doppio uses Google user data only to provide or improve prominent user-facing Doppio features, maintain security, comply with law, or complete another transfer expressly permitted by those policies. We do not allow personnel or contractors to read Google user data unless the user has affirmatively authorised access to specific data, access is necessary for security or abuse investigation, access is required by law, or the data has been aggregated and anonymised for lawful internal operations.
Service providers and disclosures
We disclose information only as needed to operate the Service, with the user's direction or consent, for security, during a lawful business transfer, or when legally required. Our principal service providers are:
| Provider | Role and information processed |
|---|---|
| Google LLC / Google Cloud / Firebase | Google sign-in, OAuth and identity tokens, Google Slides and Apps Script processing, Firebase Authentication, Firestore storage and synchronisation, and associated cloud logging. This may include account identity, presentation identifiers and content, events, polls, takeaways, cursor state, results, and diagnostics. |
| DigitalOcean, LLC | Hosts Doppio's API, WebSocket, chart, and preview services and processes service requests, presenter content, participant traffic, IP addresses, and operational logs. |
| Redis Cloud (Redis) | Provides short-lived in-memory storage for live rooms, vote counts, anonymous voter identifiers, and duplicate-vote controls. |
| Vercel Inc. | Hosts Doppio web applications, including the participant experience, dashboard, and documentation, and processes standard web request and deployment logs. |
| PostHog, Inc. | Provides product analytics and limited participant session replay as described above. It receives pseudonymous or presenter-linked product events and technical information. |
| Functional Software, Inc. (Sentry) | Provides application error tracking and performance monitoring for Doppio's services and for diagnostic reports sent by the Chrome extension. It receives error types, messages, stack traces, browser user agent, correlation tokens, and the slide and event identifiers associated with a fault. |
Google and the Chrome Web Store also process information independently under their own privacy terms when users maintain a Google account, install an application, or use Google Slides. Doppio does not control those independent activities.
We may disclose information to professional advisers, contractors, regulators, courts, or law enforcement where reasonably necessary and legally permitted. If Doppio is involved in a merger, acquisition, financing, reorganisation, or sale of assets, we will follow applicable notice and consent requirements, including Google Limited Use restrictions.
We do not currently disclose Google user data to advertising providers, data brokers, or information resellers.
Storage locations and international transfers
Doppio is operated from Australia. Our providers may process information in Australia, the European Union, the United States, and other countries where they or their subprocessors operate. In particular, Doppio uses Google/Firebase and Redis infrastructure in or associated with the Australia region where configured, DigitalOcean infrastructure for application services, Vercel's global hosting network, and the European Union service endpoints of PostHog and Sentry.
When information is transferred across borders, we use provider data-protection terms and other safeguards required by applicable law. Privacy and government-access rules in a destination country may differ from those in your country.
Retention
We retain information only while it serves the purposes described above, subject to these operational periods:
| Information | Usual retention |
|---|---|
| Live room and vote-control state in Redis | Automatically expires after inactivity, generally within 1 hour and no later than 4 hours for an active presentation room. Aggregated results may be copied to Firestore before expiry. |
| Events, polls, takeaways, settings, collaborators, and results | Retained in Firestore until the presenter deletes the applicable content or account, or asks us to delete it. Deleting a poll removes it from active use, but associated result/history records may remain until the event or account is deleted. |
| Participant browser state | Remains on the device until it expires under the application's logic or the participant clears site data. A participant can clear it at any time through browser settings. |
| Extension browser state | Remains on the device until sign-out, removal by the user, clearing extension data, or uninstalling the extension, depending on the item. |
| Product analytics | Retained for up to 12 months, then deleted or aggregated. |
| Application and security logs | Normally retained for up to 90 days. Logs connected to an active security investigation may be kept until the matter is resolved and any legal retention period ends. |
| Support correspondence | Retained for up to 24 months after the request is closed, unless a longer period is required for an active dispute or by law. |
| Deletion backups | Residual copies may remain in encrypted provider backups for up to 35 days before being overwritten. They are not restored except for disaster recovery. |
We may retain a minimal record of a deletion request, transaction, consent, security event, or legal hold when required to demonstrate compliance, resolve disputes, or protect the Service. We delete or de-identify information when the relevant period ends.
Your choices, access, and deletion
Delete Doppio content or an account
Presenters can delete an individual poll or takeaway in the Doppio sidebar and can manage events and results through the presenter interface where those controls are available. To permanently delete an event, all results, support data, or the entire Doppio account, email sam@doppio.live from the account address and state what you want deleted.
We may verify the request before acting. We will complete a verified deletion request within 30 days unless applicable law permits or requires longer. Account deletion ends access to active presentations and dashboards. Export anything you need before requesting deletion. If an account is managed by an employer or school, we may refer the request to that organisation's administrator.
Revoke Google access or unlink Doppio
You can revoke Doppio's Google access from the Google Account third-party connections page, sign out of the extension, remove the Workspace add-on, or uninstall the Chrome extension. Revoking access stops future Google API access but does not automatically delete information already stored by Doppio. Use the deletion procedure above if you also want stored Doppio data removed.
Clear local participant or extension information
Participants can clear Doppio cookies and site data in their browser. Presenters can sign out, clear the extension's stored data, or uninstall the extension. Clearing local information may remove saved sign-in state, vote confirmations, settings, or recovery information.
Privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; or complain to a privacy regulator. To exercise a right, email sam@doppio.live. Withdrawing consent does not affect processing already carried out lawfully and may prevent some features from working.
Australian users may contact the Office of the Australian Information Commissioner if they remain dissatisfied after contacting us. Users elsewhere may contact their local data-protection authority.
Cookies and local storage
Doppio uses browser and extension storage for authentication, security, participant session and vote state, preferences, reliability, and analytics. PostHog may use cookies or local storage to maintain a pseudonymous analytics identity. We do not use third-party advertising cookies. Blocking or clearing essential storage may sign you out, remove voting history, or prevent parts of the Service from working correctly.
Security and incident response
We use safeguards appropriate to the nature of the information, including HTTPS/TLS in transit, provider encryption at rest, scoped Google permissions, signed authentication tokens, access controls, environment-managed secrets, input validation, rate limiting, and separation of short-lived live state from persistent records. Access to production systems and user content is limited to authorised people with a work-related need.
No service can guarantee absolute security. We investigate suspected incidents, contain and remediate confirmed incidents, preserve necessary evidence, and notify affected users and regulators when required by applicable law. Please report a suspected security or privacy issue promptly to sam@doppio.live.
Personnel access
Doppio personnel and contractors may access account information, logs, or user content only to provide requested support with permission, operate or repair the Service, investigate security or abuse, comply with law, or work with aggregated and anonymised information. Access must be limited to what is necessary and subject to confidentiality and security obligations.
Children, students, and managed accounts
Doppio is not directed to children under 13 as account-holding presenters, and children under 13 must not create a Doppio presenter account. A school, teacher, employer, or other organisation may allow students or managed users to participate in a Doppio session when it has the authority, notices, consents, and safeguards required by applicable law. Participants are not asked for a name or email address by default.
Presenters and organisations must not use Doppio to solicit unnecessary personal or sensitive information from participants through poll questions or takeaways. If you believe a child has supplied personal information without appropriate authorisation, contact us so we can investigate and delete it.
Changes to this policy
We may update this policy to reflect changes to the Service, providers, law, or our practices. We will post the revised policy at this URL and update the date above.
If our data handling practices change at any point after you install the Chrome extension or the Workspace add-on, we will notify you of that change directly rather than relying on a silent update to this page. If a change materially expands how we use Google user data or other personal information, we will provide prominent notice and obtain consent before the new use where Google policy or applicable law requires it.
Contact
For privacy questions, rights requests, complaints, security reports, or data deletion, contact:
Sam Bessey — Doppio
Email: sam@doppio.live
Location: Victoria, Australia
We aim to acknowledge privacy and deletion requests within 7 days.